WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 11,501–11,550 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 231 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Cross-Site Request Forgery Giveaways and Contests <= 2.7.1 - Cross-Site Request Forgery via reset_installation Function No login needed ≤ 2.7.1 CVE-2024-12545 Wordfence
6.1 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Reflected Cross-Site Scripting via smc_settings_tab, unattachfixit-action, and woofixit-action Parameters No login needed ≤ 3.23 CVE-2024-11974 Wordfence
6.1 Medium WP Compress – Instant Performance & Speed Optimization Plugin wp-compress-image-optimizer Cross-Site Scripting Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting via custom_server Parameter No login needed ≤ 6.30.03 CVE-2024-12047 Wordfence
4.3 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 1.0.15 CVE-2024-12237 Wordfence
4.3 Medium WP Job Portal – A Complete Recruitment System for Company or Job Board website Plugin Broken Access Control A Complete Recruitment System for Company or Job Board website <= 2.2.4 - Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 2.2.4 CVE-2024-12132 Wordfence
5.4 Medium Post Teaser Plugin post-teaser Broken Access Control Auth. Broken Access Control ≤ 4.1.5 CVE-2022-45811 Patchstack
5.3 Medium WP Table Manager Plugin wp-table-manager Broken Access Control No login needed ≤ 3.5.2 Fixed in 3.5.3 CVE-2022-47601 Patchstack
5.4 Medium GiveWP Plugin give Broken Access Control Arbitrary Content Deletion ≤ 2.25.1 Fixed in 2.25.2 CVE-2023-23672 Patchstack
5.4 Medium WoodMart Theme woodmart Broken Access Control ≤ 7.2.1 Fixed in 7.2.2 CVE-2023-32240 Patchstack
4.3 Medium ARMember Premium Plugin armember Broken Access Control ≤ 5.9.2 Fixed in 5.9.3 CVE-2023-39994 Patchstack
6.5 Medium Analytify Plugin wp-analytify Privilege Escalation Google Analytics Dashboard plugin <= 4.2.3 - Privilege Escalation No login needed ≤ 4.2.3 Fixed in 4.3.0 CVE-2022-45830 Patchstack
6.5 Medium Putler Connector for WooCommerce Plugin woocommerce-putler-connector Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.12.0 Fixed in 2.13.0 CVE-2023-40327 Patchstack
5.4 Medium 10Web Map Builder for Google Maps Plugin wd-google-maps Broken Access Control Notice Dismissal ≤ 1.0.73 Fixed in 1.0.74 CVE-2023-45272 Patchstack
6.5 Medium IMPress Listings Plugin wp-listings Broken Access Control No login needed ≤ 2.6.2 CVE-2023-45633 Patchstack
4.3 Medium Gallery Images Ape Plugin gallery-images-ape Broken Access Control Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control ≤ 2.2.8 CVE-2022-41995 Patchstack
4.3 Medium Subscribe to Category Plugin subscribe-to-category Broken Access Control WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to Broken Access Control ≤ 2.7.4 CVE-2022-43476 Patchstack
4.3 Medium LuckyWP Scripts Control Plugin luckywp-scripts-control Broken Access Control ≤ 1.2.1 Fixed in 1.2.2 CVE-2023-47778 Patchstack
4.3 Medium 10WebAnalytics Plugin wd-google-analytics Broken Access Control ≤ 1.2.12 CVE-2023-47807 Patchstack
5.3 Medium Porto Theme - Functionality Plugin porto-functionality Broken Access Control No login needed ≤ 2.12.1 Fixed in 2.12.1 CVE-2023-48739 Patchstack
4.3 Medium FS Poster Plugin fs-poster Cross-Site Request Forgery No login needed ≤ 6.5.8 Fixed in 6.5.9 CVE-2024-37237 Patchstack
4.3 Medium WP Job Manager - Resume Manager Plugin wp-job-manager-resumes Cross-Site Request Forgery No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-37241 Patchstack
5.4 Medium Uncanny Toolkit Pro for LearnDash Plugin uncanny-toolkit-pro Cross-Site Request Forgery No login needed < 4.1.4.1 Fixed in 4.1.4.1 CVE-2024-37438 Patchstack
4.3 Medium Schema Lite Theme schema-lite Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2024-37452 Patchstack
5.4 Medium BuddyBoss Theme buddyboss-theme Cross-Site Request Forgery No login needed ≤ 2.4.61 Fixed in 2.5.01 CVE-2024-37925 Patchstack
4.3 Medium Point Theme point Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-37931 Patchstack
4.3 Medium i-amaze Theme i-amaze Cross-Site Request Forgery No login needed ≤ 1.3.7 CVE-2024-38731 Patchstack
4.3 Medium Patricia Blog Theme patricia-blog Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2024-38732 Patchstack
4.3 Medium i-transform Theme i-transform Cross-Site Request Forgery No login needed ≤ 3.0.9 CVE-2024-38764 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.69.234 Fixed in 1.70.236 CVE-2024-38778 Patchstack
6.5 Medium Coins MarketCap Plugin coins-marketcap Cross-Site Scripting ≤ 5.5.8 Fixed in 5.5.9 CVE-2024-56257 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-56268 Patchstack
6.5 Medium ConvertCalculator Plugin convertcalculator Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56302 Patchstack
6.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control ≤ 5.8 Fixed in 5.9 CVE-2024-56266 Patchstack
6.6 Medium ACF City Selector Plugin acf-city-selector Arbitrary File Upload ≤ 1.14.0 Fixed in 1.15.0 CVE-2024-56264 Patchstack
6.5 Medium GS Shots for Dribbble Plugin gs-dribbble-portfolio Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-56263 Patchstack
6.5 Medium GS Coaches Plugin gs-coach Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-56262 Patchstack
6.5 Medium Project Showcase Plugin gs-projects Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56261 Patchstack
6.5 Medium ShopElement Plugin shopelement Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-56260 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting ≤ 2.3.84 Fixed in 2.3.85 CVE-2024-56259 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.3.20 Fixed in 1.3.21 CVE-2024-56258 Patchstack
4.3 Medium AyeCode Connect Plugin ayecode-connect Broken Access Control ≤ 1.3.8 Fixed in 1.3.9 CVE-2024-56255 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-56254 Patchstack
5.4 Medium Data Tables Generator by Supsystic Plugin data-tables-generator-by-supsystic Broken Access Control ≤ 1.10.36 Fixed in 1.10.37 CVE-2024-56253 Patchstack
6.5 Medium Enter Addons Plugin enteraddons Cross-Site Scripting ≤ 2.1.9 Fixed in 2.2.1 CVE-2024-56252 Patchstack
4.3 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Cross-Site Request Forgery No login needed ≤ 5.0.28.decaf Fixed in 5.0.31.decaf CVE-2024-56251 Patchstack
4.9 Medium WPMasterToolKit Plugin wpmastertoolkit Path Traversal Arbitrary File Download ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56248 Patchstack
6.5 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting ≤ 4.0.4 Fixed in 4.0.5 CVE-2024-56246 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.42 Fixed in 2.1.43 CVE-2024-56245 Patchstack
5.4 Medium Ashe Extra Plugin ashe-extra Broken Access Control ≤ 1.2.92 Fixed in 1.3 CVE-2024-56244 Patchstack
4.3 Medium WPSSO Core Plugin wpsso Broken Access Control ≤ 18.18.1 Fixed in 18.18.2 CVE-2024-56243 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only